11 September 2026: Cybersecurity incident and vulnerability reporting begins
Under the EU Cyber Resilience Act (CRA), manufacturers will be required to report actively exploited vulnerabilities and severe cybersecurity incidents affecting their products through the EU Single Reporting Platform.
Reporting timeline
Early warning
From the moment the manufacturer becomes aware.
Full notification
A comprehensive initial assessment of the incident or vulnerability.
14 days / 1 month
Within 14 days after a corrective measure for a vulnerability; within one month after the 72-hour submission for a severe incident.
Which products are in scope?
The CRA covers “products with digital elements” whose intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Product-specific exclusions and interactions with other EU legislation require separate assessment.
Main CRA obligations apply from 11 December 2027
The reporting duties starting on 11 September 2026 are part of the transition. Most core product cybersecurity and vulnerability-handling obligations will fully apply from 11 December 2027.
Maximum penalty
Non-compliance with the essential cybersecurity requirements and Articles 13 and 14 may result in administrative fines of up to EUR 15 million or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher. Corrective or restrictive market-surveillance measures may also apply.
Start preparing now
NexusTest supports manufacturers with CRA scope assessment, product cybersecurity risk assessment, vulnerability management, incident response and reporting readiness, technical documentation and conformity-assessment roadmaps.
This content is for general information and does not replace product- or company-specific legal or regulatory advice.
